Is Calendly HIPAA Compliant for Scheduling Therapy Appointments? Yes—on eligible plans with a BAA
Overview of HIPAA Compliance
HIPAA compliance for scheduling tools means safeguarding Protected Health Information (PHI) under the HIPAA Privacy Rule and HIPAA Security Rule. In practice, that requires confidentiality, integrity, and availability controls; access management; audit readiness; and vendor contracts that meet healthcare compliance requirements.
Because a named person booking with a therapist at a date and time reveals that the individual is receiving healthcare, appointment details are typically PHI. That makes a scheduler part of your compliance scope, not just a convenience layer. Regulators also note that even unauthenticated booking pages can collect PHI depending on what is captured. ([portal.dmh.mo.gov](https://portal.dmh.mo.gov/Docs/HIPAA%20Provider%20Training%202026%20includes%20SSA%20accessible.pdf?utm_source=openai))
What about Calendly specifically? In principle, a general scheduler could be HIPAA-ready if the vendor signs a Business Associate Agreement (BAA) and you configure controls appropriately—hence the “yes—on eligible plans with a BAA.” However, as of September 3, 2026, Calendly states it is not designed to collect PHI and does not offer a BAA. ([calendly.com](https://calendly.com/help/notetaker-faq?utm_source=openai))
Importance of Business Associate Agreements
If you are a Covered Entity (or a Business Associate acting for one), any vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a Business Associate Agreement. The BAA contractually obligates the vendor to safeguard PHI, follow the HIPAA Privacy Rule and HIPAA Security Rule, report incidents, and support your compliance program. Without a BAA in place, using the tool for PHI is not HIPAA compliant—regardless of how secure the software is. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
For scheduling, that means you need a signed BAA before a single appointment tied to patient identity flows through the platform (including intake forms, reminders, calendar invites, and integrations that echo booking details). ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Risks of Using Non-Compliant Scheduling Tools
Using a scheduler that lacks a BAA can expose PHI through booking forms, page trackers, invite text, or synced calendars. OCR guidance explains that even public-facing appointment pages may involve PHI, which must be handled under the HIPAA Privacy and Security Rules. Violations can trigger investigations, corrective-action plans, and civil penalties, in addition to reputational harm. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?_cldee=lPZ1lOU9AuHulJ0xqModDJuyExHQY6_wqJ4C6DsPCabicfXRKDOJUzmsIhOE52Rw&esid=7c836209-e52f-ef11-840a-000d3a36cb89&recipientid=contact-e224ab3ac7cfe81180d102bfc0a80172-1fd998d7b4884ba8a419b2663c1759da&utm_source=openai))
Operationally, non-compliant tools fragment records, complicate access controls, and weaken audit trails. You also inherit data mapping and breach-response challenges because PHI can spread into email, calendars, and third-party apps connected to the scheduler. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?_cldee=lPZ1lOU9AuHulJ0xqModDJuyExHQY6_wqJ4C6DsPCabicfXRKDOJUzmsIhOE52Rw&esid=7c836209-e52f-ef11-840a-000d3a36cb89&recipientid=contact-e224ab3ac7cfe81180d102bfc0a80172-1fd998d7b4884ba8a419b2663c1759da&utm_source=openai))
Alternatives with HIPAA Compliance
Acuity Scheduling (Squarespace): HIPAA support is available on Premium or Powerhouse plans with a signed BAA; enable the HIPAA features before handling PHI. ([help.acuityscheduling.com](https://help.acuityscheduling.com/hc/en-us/articles/16689567523597-Acuity-Scheduling-and-HIPAA?utm_source=openai))
SimplePractice: EHR with integrated scheduling; the platform provides a BAA and is designed to meet healthcare compliance requirements. ([support.simplepractice.com](https://support.simplepractice.com/hc/en-us/articles/360018696052-SimplePractice-BAA-Terms-of-Service-and-Trust-Security-information?utm_source=openai))
TherapyNotes: EHR-first workflow with client scheduling; HIPAA controls and BAA coverage are documented in their support materials. ([support.therapynotes.com](https://support.therapynotes.com/hc/en-us/articles/49471054973851-FAQ-TherapyNotes-Terms-of-Service-Privacy-Policies-and-Business-Associate-Agreement?utm_source=openai))
Jane App: Practice management and scheduling; the company indicates HIPAA readiness and will work with you to execute a BAA. ([jane.app](https://jane.app/guide/is-jane-hipaa-compliant?utm_source=openai))
Cal.com: Healthcare-focused scheduling option that advertises HIPAA support with a signed BAA for PHI workflows. ([cal.com](https://cal.com/scheduling/healthcare?utm_source=openai))
Always confirm current terms, BAA availability, and scope (which features are covered) before you migrate booking flows. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Best Practices for Scheduling Therapy Appointments
Require a signed BAA with any vendor that will touch PHI (scheduler, messaging, telehealth, storage). Map integrations to avoid accidental PHI leakage. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Minimize PHI in booking flows: avoid diagnosis, symptoms, or free-text health details; keep invites neutral; prefer portal links for sensitive information. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?_cldee=lPZ1lOU9AuHulJ0xqModDJuyExHQY6_wqJ4C6DsPCabicfXRKDOJUzmsIhOE52Rw&esid=7c836209-e52f-ef11-840a-000d3a36cb89&recipientid=contact-e224ab3ac7cfe81180d102bfc0a80172-1fd998d7b4884ba8a419b2663c1759da&utm_source=openai))
Harden security: enforce multi-factor authentication, role-based access, and least-privilege; prefer mature data encryption standards (TLS in transit, AES-256 at rest). ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Standardize reminder content to limit PHI; allow confidential communications requests and respect patient channel preferences. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/198/may-health-care-providers-leave-messages/index.html?utm_source=openai))
Integrate scheduling with your EHR to centralize audit logs and reduce duplicate PHI in email/calendars. ([support.therapynotes.com](https://support.therapynotes.com/hc/en-us/articles/30661181330715-System-Security-and-User-Responsibilities?utm_source=openai))
Understanding Protected Health Information (PHI)
PHI is individually identifiable health information related to health, care delivery, or payment. In scheduling, a client’s identity connected to a therapy appointment date/time is typically PHI, even if no diagnosis is mentioned. Treat booking details, reminders, calendar entries, and intake answers as PHI unless properly de-identified. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html?Channel=Google_PPC&field_insight_category_target_id=2&utm_source=openai))
Because booking pages and embedded forms can transmit PHI to the scheduler and to analytics scripts, limit data collected and use HIPAA-ready vendors with BAAs. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?_cldee=lPZ1lOU9AuHulJ0xqModDJuyExHQY6_wqJ4C6DsPCabicfXRKDOJUzmsIhOE52Rw&esid=7c836209-e52f-ef11-840a-000d3a36cb89&recipientid=contact-e224ab3ac7cfe81180d102bfc0a80172-1fd998d7b4884ba8a419b2663c1759da&utm_source=openai))
Steps to Ensure Secure Appointment Scheduling
Determine your role (Covered Entity or Business Associate) and document your healthcare compliance requirements. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Inventory data flows for scheduling (forms, invites, reminders, calendar sync, analytics) and identify PHI touchpoints. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?_cldee=lPZ1lOU9AuHulJ0xqModDJuyExHQY6_wqJ4C6DsPCabicfXRKDOJUzmsIhOE52Rw&esid=7c836209-e52f-ef11-840a-000d3a36cb89&recipientid=contact-e224ab3ac7cfe81180d102bfc0a80172-1fd998d7b4884ba8a419b2663c1759da&utm_source=openai))
Select a HIPAA-capable scheduler and execute a BAA before moving any PHI. Verify which features are in-scope under the BAA. ([help.acuityscheduling.com](https://help.acuityscheduling.com/hc/en-us/articles/16689567523597-Acuity-Scheduling-and-HIPAA?utm_source=openai))
Configure security controls: 2FA, access roles, data retention, minimal invite content, and vetted integrations; confirm data encryption standards. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Integrate with your EHR to consolidate PHI, reminders, and audit trails; train staff on minimum necessary use and incident response. ([support.therapynotes.com](https://support.therapynotes.com/hc/en-us/articles/30661181330715-System-Security-and-User-Responsibilities?utm_source=openai))
Monitor and test: review logs, run tabletop exercises, and reassess vendors annually or after major product changes. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html?utm_source=openai))
Summary
HIPAA-compliant scheduling for therapy requires a signed BAA and strong security controls. Calendly currently does not offer a BAA and is not intended for PHI, so it is not suitable for patient scheduling today. Choose a HIPAA-ready alternative, enable its healthcare features, and keep PHI inside systems that are covered under executed BAAs. ([calendly.com](https://calendly.com/help/notetaker-faq?utm_source=openai))
FAQs.
Does Calendly provide a Business Associate Agreement for HIPAA compliance?
No. As of July–August 2026, Calendly states it is not designed to collect PHI and does not offer a BAA. ([calendly.com](https://calendly.com/help/notetaker-faq?utm_source=openai))
Can therapy appointments be scheduled securely using Calendly?
Not for PHI. A person’s identity linked to a therapy appointment is PHI, and without a BAA you cannot treat Calendly as a HIPAA-compliant system of record. At most, some practices use it for non-patient inquiries while instructing people not to share health details—but therapy scheduling itself should use a HIPAA-ready platform. ([portal.dmh.mo.gov](https://portal.dmh.mo.gov/Docs/HIPAA%20Provider%20Training%202026%20includes%20SSA%20accessible.pdf?utm_source=openai))
What are the risks of using non-HIPAA compliant scheduling software?
Regulatory exposure, breach notification and remediation costs, audit gaps, and reputational damage. OCR warns that appointment pages and tracking technologies can capture PHI, which must be handled under the Privacy and Security Rules. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html?_cldee=lPZ1lOU9AuHulJ0xqModDJuyExHQY6_wqJ4C6DsPCabicfXRKDOJUzmsIhOE52Rw&esid=7c836209-e52f-ef11-840a-000d3a36cb89&recipientid=contact-e224ab3ac7cfe81180d102bfc0a80172-1fd998d7b4884ba8a419b2663c1759da&utm_source=openai))
Which platforms are HIPAA compliant for appointment scheduling?
Examples include Acuity Scheduling’s HIPAA-enabled plans (with BAA), SimplePractice, TherapyNotes, Jane App, and Cal.com (with BAA). Always verify current terms, execute the BAA, and enable healthcare features before handling PHI. ([help.acuityscheduling.com](https://help.acuityscheduling.com/hc/en-us/articles/16689567523597-Acuity-Scheduling-and-HIPAA?utm_source=openai))
Table of Contents
- Overview of HIPAA Compliance
- Importance of Business Associate Agreements
- Risks of Using Non-Compliant Scheduling Tools
- Alternatives with HIPAA Compliance
- Best Practices for Scheduling Therapy Appointments
- Understanding Protected Health Information (PHI)
- Steps to Ensure Secure Appointment Scheduling
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.